Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.9
CVE-2018-19132EPSS 6%

Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet.

Fix: 4.4+
Fix from $1,600 2018-11-09
Debian Linux CRITICAL 9.8
CVE-2018-19115

keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, becaus…

Fix: 2.0.7+
Fix from $2,300 2018-11-08
Debian Linux MEDIUM 6.5
CVE-2018-19107

In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-bas…

Patch available
Fix from $1,600 2018-11-08
Debian Linux MEDIUM 6.5
CVE-2018-19108

In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an…

Patch available
Fix from $1,600 2018-11-08
Debian Linux HIGH 7.5
CVE-2018-19052EPSS 14%

An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single dir…

Fix: 1.4.50+
Fix from $1,950 2018-11-07
Debian Linux HIGH 7.5
CVE-2018-16472

A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inhe…

Fix: after 1.0.1
Fix from $1,950 2018-11-06
Debian Linux HIGH 7.8
CVE-2018-9516

In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local …

Patch available
Fix from $1,950 2018-11-06
Debian Linux HIGH 7.8
CVE-2018-9422

In get_futex_key of futex.c, there is a use-after-free due to improper locking. This could lead to local escalation of privilege with no additional p…

Patch available
Fix from $1,950 2018-11-06
Debian Linux HIGH 8.1
CVE-2018-18820EPSS 49%

A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP cl…

Fix: 2.4.4+
Fix from $1,950 2018-11-05
Debian Linux MEDIUM 6.5
CVE-2018-18897

An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo.

No fix yet
Fix from $1,600 2018-11-02
Debian Linux MEDIUM 6.5
CVE-2016-2120

An issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 allowing an authorized user to crash the server b…

Fix: after 4.0.1
Fix from $1,600 2018-11-01
Debian Linux HIGH 8.8
CVE-2018-14651

It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authentica…

Fix: after 4.1.4
Fix from $1,950 2018-10-31
Debian Linux MEDIUM 6.5
CVE-2018-14661

It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vuln…

Mitigation only
Fix from $1,600 2018-10-31
Debian Linux HIGH 7.8
CVE-2018-18718

An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the add_themes_from_dir method in dlg-contact-sheet.c becaus…

Fix: after 3.6.2
Fix from $1,950 2018-10-29
Debian Linux HIGH 8.8
CVE-2018-15688

A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected…

Patch available
Fix from $1,950 2018-10-26
Crossroads HIGH 7.8
CVE-2018-18654

Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a world-writable subdirectory in …

Mitigation only
Fix from $1,950 2018-10-26
Debian Linux MEDIUM 5.5
CVE-2018-18605

A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File Descriptor (BFD) library (aka …

No fix yet
Fix from $1,600 2018-10-23
Debian Linux MEDIUM 5.5
CVE-2018-18606

An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binu…

No fix yet
Fix from $1,600 2018-10-23
Debian Linux MEDIUM 5.5
CVE-2018-18607

An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2…

No fix yet
Fix from $1,600 2018-10-23
Debian Linux MEDIUM 6.5
CVE-2018-18584

In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum bloc…

Fix: 1.8+
Fix from $1,600 2018-10-23
Debian Linux HIGH 8.8
CVE-2018-18557EPSS 15%

LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.…

No fix yet
Fix from $1,950 2018-10-22
Debian Linux HIGH 7.5
CVE-2018-18541

In Teeworlds before 0.6.5, connection packets could be forged. There was no challenge-response involved in the connection build up. A remote attacker…

Fix: 0.6.5+
Fix from $1,950 2018-10-20
Debian Linux HIGH 8.6
CVE-2018-18284EPSS 16%

Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.

Patch available
Fix from $1,950 2018-10-19
Debian Linux MEDIUM 6.5
CVE-2018-18520

An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar…

Fix: after 0.174
Fix from $1,600 2018-10-19
Debian Linux MEDIUM 5.5
CVE-2018-18521

Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (…

Patch available
Fix from $1,600 2018-10-19
Debian Linux CRITICAL 9.8
CVE-2018-4013EPSS 10%

An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specia…

No fix yet
Fix from $2,300 2018-10-19
Debian Linux CRITICAL 9.8
CVE-2018-5188

Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presum…

Fix: 52.9 / 60.1.0+
Fix from $2,300 2018-10-18
Debian Linux CRITICAL 9.8
CVE-2018-5187

Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Fix: 60.0 / 60.1.0+
Fix from $2,300 2018-10-18
Debian Linux MEDIUM 5.5
CVE-2018-15378

A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to…

Fix: 0.100.2+
Fix from $1,600 2018-10-15
Debian Linux MEDIUM 6.3
CVE-2018-18073

Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack…

Patch available
Fix from $1,600 2018-10-15